Jr. Cyber Security Engineer
Job Description
Join By Light Professional IT Services LLC to support DoD software application development with cybersecurity engineering, requirements, and testing.
Responsibilities
- Define cybersecurity requirements for software applications aligned to program requirements and objectives
- Recommend ways to embed security engineering practices across the system development lifecycle
- Assess cybersecurity requirement compliance using manual and automated software analysis tools and methods; present findings to the customer as needed
- Conduct adversarial assessments using offensive tools, techniques, and methods against network-enabled and web applications to uncover weaknesses, gaps, and vulnerabilities
- Propose mitigations and countermeasures to reduce or eliminate software-level threats
- Interface directly with the software development team to apply software security engineering principles throughout the system development lifecycle
Requirements
- Bachelor’s Degree in Computer Science, Engineering, Cybersecurity, IT or related field required; professional and/or military experience may be substituted in lieu of degree
- Must meet IAT Level II requirements under DoD 8140 baseline certifications
- IAT Level II certification required immediately upon hire
- Maintain certification currency through continuing education as specified by the certification authority
- Experience with software engineering, development, and/or systems engineering across all phases of the system development lifecycle
- Systems administration skills including Linux; security settings, services, and hardening using STIGs and security policies; shell scripting or Python is a plus
- Ability to troubleshoot and recover from unexpected adverse configuration changes and provide advisory support
- Knowledge of threat assessment and solutions to mitigate or eliminate threats
- Experience with offensive security tools and adversarial techniques and methods
- Experience implementing software application solutions to comply with NIST SP 800-53 security controls
- Skills in compliance and vulnerability reporting and other formal technical documentation
- Understanding of Risk and Compliance Frameworks
Technologies
- Linux
- STIGs
- Security policies
- Shell scripting
- Python
- NIST SP 800-53
Preferred Experience / Qualifications
- Understanding of DoD acquisition processes and relevant cyber security processes, including the Risk Management Framework (RMF)
- Security+ certification
Benefits
- Medical, Dental & Vision Coverage
- Wellness Program
- 401(k) Matching
- Disability (Short Term & Long Term)
- Employee Assistance Program
- Life Insurance
- Education & Training
- Generous Leave Policy: 11 Federal Holidays, PTO, Military Leave, Bereavement and Jury Duty
Security Clearance / Special Requirements
- U.S. Citizenship required due to government contract requirements
- Current SECRET security clearance required
- Ability to attain TOP SECRET/SCI clearance
- Security clearance requirements will be specified in the Government’s Task Order
- On-site role in Orlando, FL; travel may be required (less than 10%)